Total CVEs

140,284

Critical Severity

3,711

High Severity

13,344

Last 7 Days

1,815
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 8,341 - 8,360 of 13,041 CVEs
CVE-2026-4645 HIGH - 7.5

A flaw was found in the `github.com/antchfx/xpath` component. A remote attacker could exploit this vulnerability by submitting crafted Boolean XPath expressions that evaluate to true. This can cause an infinite loop in the `logicalQuery.Select` function, leading to 100% CPU utilization and a Denial ...

Published: Mar 23, 2026
Source: NVD
CVE-2026-32969 HIGH - 7.5

An unauthenticated remote attacker can exploit a Pre-Auth blind SQL Injection vulnerability in the userinfo endpointโ€™s authentication method due to improper neutralization of special elements in a SQL SELECT command. This can result in a total loss of confidentiality.

Vendor: MB connect line, Helmholz
Product: MB connect line mbCONNECT24, mymbCONNECT24, myREX24V2, myREX24V2.virtual
Published: Mar 23, 2026
Source: NVD
CVE-2026-4581 HIGH - 7.3

A weakness has been identified in code-projects Simple Laundry System 1.0. Affected is an unknown function of the file /checklogin.php of the component Parameters Handler. This manipulation of the argument Username causes sql injection. The attack is possible to be carried out remotely. The exploit ...

Published: Mar 23, 2026
Source: NVD
CVE-2026-4580 HIGH - 7.3

A security flaw has been discovered in code-projects Simple Laundry System 1.0. This impacts an unknown function of the file /checkupdatestatus.php of the component Parameters Handler. The manipulation of the argument serviceId results in sql injection. The attack can be executed remotely. The explo...

Published: Mar 23, 2026
Source: NVD
CVE-2026-4579 HIGH - 7.3

A vulnerability was identified in code-projects Simple Laundry System 1.0. This affects an unknown function of the file /viewdetail.php of the component Parameters Handler. The manipulation of the argument serviceId leads to sql injection. Remote exploitation of the attack is possible. The exploit i...

Published: Mar 23, 2026
Source: NVD
CVE-2026-23555 HIGH - 7.1

Any guest issuing a Xenstore command accessing a node using the (illegal) node path "/local/domain/", will crash xenstored due to a clobbered error indicator in xenstored when verifying the node path. Note that the crash is forced via a failing assert() statement in xenstored. In case xen...

Vendor: Xen
Product: Xen
Published: Mar 23, 2026
Source: NVD
CVE-2026-23554 HIGH - 7.8

The Intel EPT paging code uses an optimization to defer flushing of any cached EPT state until the p2m lock is dropped, so that multiple modifications done under the same locked region only issue a single flush. Freeing of paging structures however is not deferred until the flushing is done, and ca...

Vendor: Xen
Product: Xen
Published: Mar 23, 2026
Source: NVD
CVE-2026-4602 HIGH - 7.5

Versions of the package jsrsasign before 11.1.1 are vulnerable to Incorrect Conversion between Numeric Types due to handling negative exponents in ext/jsbn2.js. An attacker can force the computation of incorrect modular inverses and break signature verification by calling modPow with a negative expo...

Vendor: jsrsasign_project
Product: jsrsasign
Published: Mar 23, 2026
Source: NVD
CVE-2026-4601 HIGH - 8.7

Versions of the package jsrsasign before 11.1.1 are vulnerable to Missing Cryptographic Step via the KJUR.crypto.DSA.signWithMessageHash process in the DSA signing implementation. An attacker can recover the private key by forcing r or s to be zero, so the library emits an invalid signature without ...

Vendor: jsrsasign_project
Product: jsrsasign
Published: Mar 23, 2026
Source: NVD
CVE-2026-4600 HIGH - 7.4

Versions of the package jsrsasign before 11.1.1 are vulnerable to Improper Verification of Cryptographic Signature via the DSA domain-parameter validation in KJUR.crypto.DSA.setPublic (and the related DSA/X509 verification flow in src/dsa-2.0.js). An attacker can forge DSA signatures or X.509 certif...

Vendor: jsrsasign_project
Product: jsrsasign
Published: Mar 23, 2026
Source: NVD
CVE-2026-4598 HIGH - 7.5

Versions of the package jsrsasign before 11.1.1 are vulnerable to Infinite loop via the bnModInverse function in ext/jsbn2.js when the BigInteger.modInverse implementation receives zero or negative inputs, allowing an attacker to hang the process permanently by supplying such crafted values (e.g., m...

Vendor: jsrsasign_project
Product: jsrsasign
Published: Mar 23, 2026
Source: NVD
CVE-2025-10679 HIGH - 7.3

The ReviewX โ€“ WooCommerce Product Reviews with Multi-Criteria, Reminder Emails, Google Reviews, Schema & More plugin for WordPress is vulnerable to arbitrary method calls in all versions up to, and including, 2.2.12. This is due to insufficient input validation in the bulkTenReviews function tha...

Vendor: reviewx
Product: ReviewX โ€“ Multi-Criteria Reviews for WooCommerce with Google Reviews & Schema
Published: Mar 23, 2026
Source: NVD
CVE-2026-4566 HIGH - 8.8

A flaw has been found in Belkin F9K1122 1.00.33. The affected element is the function formWISP5G of the file /goform/formWISP5G. Executing a manipulation of the argument webpage can lead to stack-based buffer overflow. The attack can be launched remotely. The exploit has been published and may be us...

Published: Mar 23, 2026
Source: NVD
CVE-2026-4565 HIGH - 8.8

A vulnerability was detected in Tenda AC21 16.03.08.16. Impacted is the function formSetQosBand of the file /goform/SetNetControlList. Performing a manipulation of the argument list results in buffer overflow. The attack can be initiated remotely. The exploit is now public and may be used.

Published: Mar 23, 2026
Source: NVD
CVE-2026-4562 HIGH - 7.3

A security flaw has been discovered in MacCMS 2025.1000.4052. This affects an unknown part of the file application/api/controller/Timming.php of the component Timming API Endpoint. The manipulation results in missing authentication. The attack may be performed from remote. The exploit has been relea...

Published: Mar 23, 2026
Source: NVD
CVE-2026-2580 HIGH - 7.5

The WP Maps โ€“ Store Locator,Google Maps,OpenStreetMap,Mapbox,Listing,Directory & Filters plugin for WordPress is vulnerable to time-based SQL Injection via the โ€˜orderbyโ€™ parameter in all versions up to, and including, 4.9.1 due to insufficient escaping on the user supplied parameter and lack of ...

Published: Mar 23, 2026
Source: NVD
CVE-2026-4558 HIGH - 8.8

A flaw has been found in Linksys MR9600 2.0.6.206937. Affected is the function smartConnectConfigure of the file SmartConnect.lua. Executing a manipulation of the argument configApSsid/configApPassphrase/srpLogin/srpPassword can lead to os command injection. The attack may be launched remotely. The ...

Published: Mar 22, 2026
Source: NVD
CVE-2026-4555 HIGH - 8.8

A weakness has been identified in D-Link DIR-513 1.10. The impacted element is the function formEasySetTimezone of the file /goform/formEasySetTimezone of the component boa. This manipulation of the argument curTime causes stack-based buffer overflow. The attack can be initiated remotely. The exploi...

Published: Mar 22, 2026
Source: NVD
CVE-2026-4553 HIGH - 8.8

A vulnerability was identified in Tenda F453 1.0.0.3. Impacted is the function fromNatlimit of the file /goform/Natlimit of the component Parameters Handler. The manipulation of the argument page leads to stack-based buffer overflow. It is possible to initiate the attack remotely. The exploit is pub...

Published: Mar 22, 2026
Source: NVD
CVE-2026-4552 HIGH - 8.8

A vulnerability was determined in Tenda F453 1.0.0.3. This issue affects the function fromVirtualSer of the file /goform/VirtualSer of the component Parameters Handler. Executing a manipulation of the argument page can lead to stack-based buffer overflow. The attack may be performed from remote. The...

Published: Mar 22, 2026
Source: NVD